Impact
goproxy, a Go-based HTTP proxy, does not apply basic authentication when handling CONNECT tunnel requests. This flaw lets an unauthenticated client open a tunnel through the proxy as if credentials had been supplied, enabling the relay of arbitrary TCP traffic. As a result, an attacker can reach internal or otherwise protected destinations by simply sending CONNECT requests, undermining the authentication model of the proxy.
Affected Systems
The vulnerable product is GoProxy from the snail007 project. Versions up to and including v15.3 do not enforce authentication on CONNECT requests, making them susceptible to attack. Any deployment of these versions that is exposed to untrusted network traffic is at risk.
Risk and Exploitability
The CVSS score of 6.9 EPSS score of <1% indicates that exploitation is currently considered low probability, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the flaw can be exploited by any remote client that can reach the proxy by sending a CONNECT request. No special privileges are required, and the attack is performed solely over standard network connections, making it a practical threat for attackers who target exposed proxy services.
OpenCVE Enrichment